North Korea-Linked Hackers Drive On-Chain Malware Surge
A recent report from Chainalysis reveals a sharp rise in on-chain malware activity, with a 420% increase this year. State-linked hackers, particularly those linked to North Korea and Iran, are responsible for most of the surge.
The analysis highlights that state-linked actors represent roughly two-thirds of new on-chain malware activity. This suggests that sophisticated and persistent malicious campaigns are becoming more integrated with blockchain-based execution and data storage.
Chainalysis points to UNC5342, a North Korea-linked group, as being connected to earlier unattributed activity across multiple ecosystems, including Tron, Aptos, and BNB Smart Chain. This implies that attackers can scale by shifting to platforms where their prior experience or infrastructure can be adapted with minimal changes.
The report also notes that public blockchains can make malicious campaigns unusually resilient. Even if domains, servers, or traditional code hosting are taken down, the data stored on-chain can remain accessible and usable for longer periods.